Do you know what an attestation actually is? Are you aware of the complete lack of accountability, liability, anything from these reports? They literally just mean “I saw some money in an account and it matched the figure they said they were supposed to have.” That’s it. As of 12:00pm on a Friday you could have your friend wire you $1B and get someone to attest that they saw $1B in your bank account, which is then wired back out; does that make you a billionaire?
The willingness of these operators to target poor, unsuspecting muppets who aren’t aware that attestation ≠ audit, without any disclaimer or explanation of this fact, is a HUGE red flag that their claims of “transparency” are anything but.
> As of 12:00pm on a Friday you could have your friend wire you $1B and get someone to attest that they saw $1B in your bank account, which is then wired back out; does that make you a billionaire?
Yes, I understand, but the businesses involved in this also have a strong desire to not become insolvent.
I think it's very reasonable to accept that you're mostly betting on Gemini (or whoever) being an honest broker, and the attestation reports give some reason to believe that they can produce the dollars on demand. The attestation reports do show that they're able to come up with that available balance, even if only for a minute, which does add credibility.
If you're concerned about the solvency of the institutions offering these products, that's fine, but I think everyone (including Tether) is incentivized to do everything possible to never become insolvent.
1) You retract your claim that the stablecoins you listed have audited reserves.
2) You’ve found the auditors’ reports and we all get some excellent reading material for the weekend.
Your theories of crypto monetary policy are completely irrelevant within the context of a regulatory conversation. Which, by the way, is the problem the entire crypto community will have — if the hammer ever drops (which may never happen due to intense lobbying pressure by VCs and Big Crypto), the regulator won’t have any patience for any of the various theories about “the future of money” etc.
Answer basic questions about audits or admit you’ve got a problem.
I suppose I'll take option #1, if we're saying that "attestations" are not a form of auditing. It seems pedantic to me, but maybe your usage is correct in the regulatory/accounting world.
It is not a full audit of the entire history of the movement of the funds.
I agree that having a full trace of every penny publicly available would increase trust in GUSD.
I suspect that if you're an exchange partner with Gemini, you could ask for more visibility into how the funds are actually being allocated when they're not being summoned for attestation.
Keep in mind that the risk here is insolvency, and the firms best suited to evaluate that risk are also the ones holding large amount of GUSD.
I don't know if regulation would be helpful here or not. I think exchanges considering holding GUSD should accept the risk of possible insolvency, and adjust their business to account for that risk, perhaps by buying insurance.
Great! So you agree that your claim that these stablecoins have audited reserves was false, and you retract it. Pleasure doing business.
Since you were a good sport about this, I’ll say that I agree that Gemini is one of the better participants in that market. That being said, I’ll leave you with the notice on page 4 of your linked document, which is the only relevant passage for legal/regulatory purposes:
This Information Has Not Been Examined by the Company’s Independent Accountant
Differentiating between and audit and attestation is not pedantic but I can understand why you might think it is. I explained there difference here: https://news.ycombinator.com/item?id=27532670
TL;DR attestations do not provide a strong level of assurance and there are no standards for conducting them - they are ad hoc engagements. Audits are standardised engagements and must conform to a particular methodology to determine sufficient and appropriate evidence that financial statements are true and fair - basically you need third party info like custodian reports.
To back up numair, and help you understand a bit better, an audit in the financial regulatory sense is a highly pedantic endeavor. Accounting can be as much artform as anything else, and even amongst all the accountant's in the world, exactly how you track money and classify things is open to interpretation, and it is very easy to report some cherry picked numbers and tell a completely different story than what is going on.
Independent audits do two things. They examine process, and create an environment where you have to operate in a sane manner, because your auditor can drop in at any time, pick out any particular starting point, and will expect to be able to have delivered to them where that transaction came from, and ultimately will go to based on GAAP and in house supporting process documents. This basically draws a complexity boundary around how exotic you can get within the context of one organization, because if one of the big independent auditors can't make heads or tails of you in a reasonable amount of time, it is a gigantic red flag w.r.t your operational processes.
An audit also results in a snapshot of your entire cash/value flow through an organization. This is verified and cross checked for valuation by someone who doesn't know you from Adam to ensure objectivity. This is just a guarantee that the numbers add up, and over time continue to make sense. Massive discontinuities that can't be ascribed to something in the real/business world measurable by someone else are also red flags that there may be something going on there that may be valid, but you need more info to get to the bottom of it to ensure it is sound.
t. Quality Assurance person who has spent entirely too much of his life digging into how finance works even though they allegedly hate it, but a statistical analysis of how much of my mind I devote to financial analysis, modeling and prediction tells another story.
Ironically, if you mentally audited my thoughts you'd easily come to the conclusion I love finance. I don't. I like measuring things. Measuring finances effectively is a pain in the ass, and a perennial issue, that there are more than a few groups constantly working to frustrate people like me who try to distill truth out of account ledgers.
That's why numair is absolutely right. An attestation is one slice. You know money was there. You don't know where it went afterward, which subtransactions it spawned (fees, taxes, interest accrual, etc...). That's what auditor's look at and collate. It's why it's a big deal. At the end of the day it's all arithmetic, and an audit is just having someone else run the numbers and vouching they get the same result. It's actually a little more than that, because regulation wise, the auditor's number is more reliable than yours, because they have all the incentives in place to keep their processes and interpretive liberty taking to a minimum. You want to match the auditor's numbers if you can coax your process into doing so... Of course again, there's arms race there as well. Note, auditor's don't find or investigate fraud. They just check your process is being followed, and that when someone else does it, everything works out. It just so happens that this is also a great way to shake out anything that might be used to as a basis to make fraud effectively doable.
It is a rabbit hole. One that I've explored many branches of, but after a while doing it, you can pretty quickly measure how uncomfortable a group is by their level of nervousness around letting an auditor drive.
Very interesting and I agree that a blog post would be great on this topic.
I think intuition is what I'm lacking here. It's unclear to me just how dangerous the situation is likely to be.
Before this discussion, my understanding was that only attestations are available, and that the company wouldn't become insolvent because the company would incur huge losses if that happened.
That's still my understanding, though now I know the difference be attestation and audits, that a complexity boundary exists due to audit resources, and that auditors don't even look for fraud (you'd think they would without knowing how this works). Thank you for the color around it, it helps me understand how people in this business think about finance.
However, I'm still of the (apparently wrong?) opinion that Gemini/Circle/Binance/Paxos at least, are staking their real businesses, with things like executive pay and employee payroll and all that, on these products. "We lost the money and our stablecoin is now worthless" should sink any of these companies.
I think we're in agreement that failure to maintain peg would sink these companies, but my conclusion was that it's very unlikely. You and numair seem to conclude that it's more than just likely, it's almost inevitable.
This tells me that my intuition is probably wrong, but it's still difficult for me to understand why a company like Gemini would decide to risk insolvency.
And even if they did release a full audit, if it can't detect fraud, then why would you trust it? I know it's better than just attestations, but I'm not sure how great the risk of fraud is relative to the risk of other routes to insolvency.
I'm not necessarily saying that there is something unsound going on, just that lack of auditor engagement is likely indicative there is a non-trivial amount of process-risk there that no one except them is privy to, and incentive-wise, they aren't going to just come out and say "it's all a house of cards, guys!"
>and that the company wouldn't become insolvent because the company would incur huge losses if that happened
Something there is parsing off to me, but I'm not going to try to pretend I have a mastery of insolvency vs. losses, but generally speaking, insolvency doesn't cause losses. Insolvency happens as the result of losses, which may be caused by any number of factors. The state of becoming insolvent itself is actually a bit of an information propagation problem, because once that state is reached, in many jurisdictions, all transactions must cease, but no one has a master "stop all business processes this instant" button.
>However, I'm still of the (apparently wrong?) opinion that Gemini/Circle/Binance/Paxos at least, are staking their real businesses, with things like executive pay and employee payroll and all that, on these products. "We lost the money and our stablecoin is now worthless" should sink any of these companies.
You are correct. They are. What you're missing there, though, is that the company != the people. Incentive problem again. If things do go belly up, the only things "lost" are company assets (equipment, patents, licensing, the brand, etc...) and "potential income" (exec pay) in the form of Stocks and equity that would need to be sold off first to realize that income, which they probably have been doing all along. No skin off their nose if they have to restart a new chain. In fact, the old one going under would make doing so easier due to the chunk of assets about to be sold off on the cheap.
The danger, at least from my understanding, is exactly tied to the holding of assets to back the stablecoin. Say everything goes up in smoke. The company gets liquidated through bankruptcy or restructured, but all of that paper they hold is not cash value. It has to be sold at market rate, and large volume paper moving can move prices in unintuitive ways. Under bankruptcy, particularly the liquidation form, most of that will sell for way below value since there will be quite literally no other choice than to sell. In fact, these stablecoins, if their USD peg is ever called to be accounted for as collateral, being in the form of held paper they state they can liquidate to cover their cash liabilities: may at any time become insolvent if something big happens in a particular sector of the market to which they have exaggerated exposure. Then again, that could pass with nary a whimper because nothing happened that required them to actually pay out that USD denomination. The risk is still there though. I've developed a waryness of anything that passes itself off as stable, but is, in fact, subject to normal market volatility. Given that it's taken me years of intentional effort just to kinda grok things to the point I semi-reliably seem to be able to explain things without a professional coming out of the wings and enlightening me to my dead wrongness 100% of the time, and the fact most everyone else doesn't bash their head bloody doing so, I tend to personally look at these as extremely likely sources of unexpected second and higher order effects.
It's a threat to market stability, because that much paper getting dumped on the market at once creates a supply glut. These stablecoins are operating like banks in a sense, without any of the controls. We now have two kinds of bank runs to worry about, one isn't audited at all, and if something were to happen, would potentially leave a rather large blast crater.
So I won't go so far as to say your opinion or outlook on these companies is wrong per se. I will say there is enough lack of information on my part I wouldn't put my money into it, and it makes me nervous what'll happen if the seeming risk check being written ever comes due. This may turn into another mess of a recession or other market shaking calamity. Like, just me thinking about it right now took me through every bit of research I've done over the last 5 years in spare time, and I'm still not even confident I've got a solid grasp of the second and higher order consequences.
What I do know, is that someone betting their business on something is never in isolation a good enough reason to put your hard earned capital into it; and I implore you to do your own research and really try to wrestle with it. It's hard, but that's capitalism. We're all capital allocators, and if we don't make the decision of how we want our hard earned capital allocated, then we're never really factoring into the invisible hand, someone else is.
Please turn this comment into a blog post or whitepaper or something, because it’s excellent and deserves way more visibility than it’s going to get 4-deep in a weekend comment thread on HN. I think we will all have to take on the task of educating a lot of kids — literally, kids — about the boring-seeming world of financial auditing. They’ll be wondering where their money went, and how to avoid such situations the next time around...
Oh God... All the bibliography building that'd go into a white paper... Ugh.
I might try spinning up a Blog one of these days when work slows down a bit. It's funny the insight you pick up having to dissect these types of things on a semi-regular basis. Financial Auditing, Risk Management, Quality Assurance, we're all doing the same schtick in different ways.
Also, I'd add that one needs to keep in mind that what I posted only covers audits of singular organizations. If you're actually up to skulduggery, as I understand it, it's almost always distributing things between multiple corporate entities, audited by different groups so that no one auditor gets a complete view of what's going on. Once you start looking at groups of entities, especially jurisdictionally distributed, the complexity balloons, and you're now firmly in financial engineering and forensic accountancy territory.
Financial engineering and forensic accountancy is a rabbit hole that I'm pretty sure encyclopedias could be written on, and would outdate themselves as quickly as you could propagate the info, as there is always an arms race going on between those wishing to move large amounts of money gained in less scrupulous ways, and those wishing to make those enterprises an impossibility.
Send me an email — numair@numair.com — I’d like to know more about what led you to do a deep-dive into these worlds, as I am sure it’s a long and interesting story!
Even breaking this down into a simple analogy, buying a house. Your mortgage broker (or lender, rather) doesn't just want a screenshot of your "Available balance", they want to see the account history and transactions, to substantiate income statements, known debts, and sources of funding.
The willingness of these operators to target poor, unsuspecting muppets who aren’t aware that attestation ≠ audit, without any disclaimer or explanation of this fact, is a HUGE red flag that their claims of “transparency” are anything but.